cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2

Vulnerabilities

Page 76 of 102
CVE-2019-8764P4MEDIUMCVSS 6.1fixed in 6.1≥ unspecified, < watchOS 6.12019-12-18
CVE-2019-8764 [MEDIUM] CWE-79 CVE-2019-8764: A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Proc A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2024-54523P4MEDIUMCVSS 6.3fixed in 11.22025-01-27
CVE-2024-54523 [MEDIUM] CWE-787 CVE-2024-54523: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
nvd
CVE-2022-32891P4MEDIUMCVSS 6.1fixed in 9.0≥ unspecified, < 9+1 more2023-02-27
CVE-2022-32891 [MEDIUM] CWE-1021 CVE-2022-32891: The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchO The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
nvd
CVE-2026-28897P4MEDIUMCVSS 6.2fixed in 26.52026-05-11
CVE-2026-28897 [MEDIUM] CWE-121 CVE-2026-28897: A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 an A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2026-43666P4MEDIUMCVSS 6.2fixed in 26.52026-05-11
CVE-2026-43666 [MEDIUM] CWE-787 CVE-2026-43666: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2021-30682P4MEDIUMCVSS 5.5fixed in 7.52021-09-08
CVE-2021-30682 [MEDIUM] CVE-2021-30682: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.
nvdapple
CVE-2019-8540P4MEDIUMCVSS 5.5fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8540 [MEDIUM] CWE-665 CVE-2019-8540: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2017-13804P4MEDIUMCVSS 5.5fixed in 4.12017-11-13
CVE-2017-13804 [MEDIUM] CWE-20 CVE-2017-13804: An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "StreamingZip" component. It allows remote attackers to write to unintended pathnames via a crafted ZIP archive.
nvdapple
CVE-2021-30773P4MEDIUMCVSS 5.5fixed in 7.6≥ unspecified, < 7.62021-09-08
CVE-2021-30773 [MEDIUM] CVE-2021-30773: An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious application may be able to bypass code signing checks.
nvd
CVE-2021-30968P4MEDIUMCVSS 5.5fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30968 [MEDIUM] CWE-59 CVE-2021-30968: A validation issue related to hard link behavior was addressed with improved sandbox restrictions. T A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to bypass certain Privacy preferences.
nvdapple
CVE-2021-30836P4MEDIUMCVSS 5.5fixed in 8.0≥ unspecified, < 82021-10-28
CVE-2021-30836 [MEDIUM] CWE-125 CVE-2021-30836: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted audio file may disclose restricted memory.
nvd
CVE-2024-44282P4MEDIUMCVSS 5.5fixed in 11.12024-10-28
CVE-2024-44282 [MEDIUM] CWE-125 CVE-2024-44282: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.7. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Parsing a file may lead to disclosure of user information.
nvd
CVE-2021-31013P4MEDIUMCVSS 5.5v8.32021-12-13
CVE-2021-31013 [MEDIUM] CVE-2021-31013: watchOS 8.3 Apple Security Update: About the security content of watchOS 8.3 Product: watchOS Version: 8.3 CVE: CVE-2021-31013 Component: FontParser Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2024-23287P4MEDIUMCVSS 5.5fixed in 10.42024-03-08
CVE-2024-23287 [MEDIUM] CWE-377 CVE-2024-23287: A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to access user-sensitive data.
nvdapple
CVE-2023-40417P4MEDIUMCVSS 5.4fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40417 [MEDIUM] CVE-2023-40417: A window management issue was addressed with improved state management. This issue is fixed in Safar A window management issue was addressed with improved state management. This issue is fixed in Safari 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2024-44240P4MEDIUMCVSS 5.5fixed in 11.12024-10-28
CVE-2024-44240 [MEDIUM] CVE-2024-44240: The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, i The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2024-44302P4MEDIUMCVSS 5.5fixed in 11.12024-10-28
CVE-2024-44302 [MEDIUM] CVE-2024-44302: The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, i The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2024-23290P4MEDIUMCVSS 5.5fixed in 10.42024-03-08
CVE-2024-23290 [MEDIUM] CWE-922 CVE-2024-23290: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to access user-sensitive data.
nvdapple
CVE-2022-32883P4MEDIUMCVSS 5.5fixed in 9.02022-09-20
CVE-2022-32883 [MEDIUM] CWE-284 CVE-2022-32883: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.
nvd
CVE-2015-5839P4MEDIUMCVSS 5.0v1.02015-09-18
CVE-2015-5839 [MEDIUM] CWE-254 CVE-2015-5839: dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app dyld in Apple iOS before 9 allows attackers to bypass a code-signing protection mechanism via an app that places a crafted signature in an executable file.
nvd
Apple watchOS vulnerabilities | cvebase